Dynamic Authentication via Organization Data Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional authentication methods relying on fixed codes or unique physical devices are vulnerable to unauthorized access, and username/password combinations face challenges from social engineering attacks and are costly for one-time password technology.

Innovation Solution

The method uses organization-based information, such as email and calendar data, to derive personalized, dynamic challenge questions for authenticating users, reducing reliance on static passwords and enhancing security with a 'mental fingerprint' that is harder to forget or lose.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If fixed codes or unique physical devices are used for authentication, then access control is implemented, but security is vulnerable to unauthorized access and social engineering attacks

Engineering Contradiction:
Improveauthentication securityVSAvoidvulnerability to unauthorized access
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent transitions from static authentication (fixed codes, passwords) to dynamic authentication using organization-based information that changes over time. The system uses current organizational data such as recent email communications, calendar events, and contact information to generate authentication challenges, making the authentication credentials dynamic and difficult to predict or compromise through social engineering.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent introduces organization-based information as an intermediary layer between the user and the authentication system. Instead of directly using personal information that could be obtained through social engineering, the system uses organizational context (email patterns, calendar data, contact lists) as a mediator to verify identity, adding a layer of security that is specific to the organizational environment and harder to compromise.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If one-time password technology is used, then security is enhanced, but costs increase

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication costs
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The system uses organization-based information that already exists within the organizational infrastructure (email systems, calendar services, contact databases) to provide authentication. This eliminates the need for separate one-time password generation systems, hardware tokens, or external verification services, allowing the organization to leverage existing resources for authentication purposes and reducing overall authentication infrastructure costs.

Inventive Principle:
Principle #25Self-service

3Ease of operation

If traditional authentication methods are used, then access control is provided, but employee satisfaction decreases due to forgotten credentials

Engineering Contradiction:
Improveemployee satisfactionVSAvoidforgotten credentials
Core Design Contradiction:
Ease of operationVSLoss of information

Solution Approach 1:

The patent changes the parameters of authentication from memorization-based (passwords, PINs) to recognition-based challenges. Instead of requiring employees to remember complex credentials, the system presents challenges based on their organizational context (recent emails, calendar events, contacts) that they naturally encounter in their work, making authentication more intuitive and less prone to being forgotten.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS8856954B1Authenticating using organization based information
Publication Date: 2014.10.07 EMC IP HLDG CO LLC
  • US8856954B1 patent drawing
  • US8856954B1 patent drawing
  • US8856954B1 patent drawing

AI summary

A method is used in authenticating using organization based information. Organization based information is analyzed for information that is suitable for use in authenticating a user. The organization based information includes employee-used information. A question is derived from the organization based information. Based on the question, a process used to authenticate a user is executed.